CKA
955 incident response problems that help with CKA prep.
먼저 읽을 가이드
추천 문제
All problems (955)
K8S-105Ingress canary header routing works for HTTP but gRPC requests ignore the split and all traffic stays on stableThe progressive delivery rule appears valid, but the gRPC path follows a different routing evaluation than the header-based HTTP test path.KubernetesAdvanced17 minProK8S-096PodSecurity admission blocks the debug container flow even though the base workload still runsThe app continues serving traffic, but emergency debugging fails because the current security profile denies the ephemeral container path.KubernetesAdvanced17 minProK8S-117Projected service account token expires and the sidecar never reloads it so calls to the cloud API fail hours laterEverything works after startup, but long-lived pods lose access because one component reads the token once and never reopens the projected file.KubernetesAdvanced17 minProK8S-1289A cluster appears healthy until a node recycleA cluster runs for months and suddenly new nodes cannot create workloads because the admission webhook is unreachable only from fresh nodes.KubernetesAdvanced18 minProK8S-146A Gateway API route binds to the correct listener, but the backendRef points at a Service in another namespace without the required ReferenceGrantEverything looks connected until cross-namespace security rules are evaluated.KubernetesAdvanced18 minProK8S-1277A node group joins the cluster but DaemonSet pods stay brokenA custom AMI or launch template brings new nodes online and only platform add-ons behave strangely on those instances.KubernetesAdvanced18 minProK8S-1281A pod restarts after every successful deploymentA rollout works on some nodes and fails on others immediately after a private endpoint or dependency address changed.KubernetesAdvanced18 minProK8S-1295A rollout stalls on only one zoneA cluster drain starts cleanly and one workload never reschedules despite enough total cluster capacity.KubernetesAdvanced18 minProK8S-1271A StatefulSet keeps rescheduling but pods stay PendingA StatefulSet keeps rescheduling but pods stay Pending focuses on storage-operations and asks the reader to isolate the key signal in AWS. A valid PVC and a healthy node pool can still deadlock if no single zone satisfies both scheduling and storage rules.KubernetesAdvanced18 minProK8S-1287A StatefulSet recovers after reboot but one member keeps attaching the wrong volumeA stateful workload is migrated or restored and one ordinal repeatedly boots with the wrong persistent data.KubernetesAdvanced18 minProK8S-312An externalTrafficPolicy Local design is correctAn externalTrafficPolicy Local design is correct focuses on cluster-networking-and-service-discovery and asks the reader to isolate Timeouts and Latency in AWS. 실무에서는 timeouts-and-latency 증상만 보고 Pod 하나에 매달리지 말고 이벤트, 이전 로그, Service/Endpoint, 최근 배포 변경을 한 번에 묶어 보는 편이 오진을 줄입니다.KubernetesAdvanced18 minProK8S-1259An ingress controller starts but health checks still failAn ingress controller starts but health checks still fail focuses on load-balancer-operations and asks the reader to isolate the key signal in AWS. Having the right tag keys is not the same as having subnets that are currently usable for the reque...KubernetesAdvanced18 minProSECURITY-106An OPA policy package rename leaves the fallback allow rule active in one cluster after a partial config rolloutMost clusters enforce the new package, but one environment silently drops into the default allow behavior because its bundle path never updated.SecurityAdvanced18 minProK8S-1232CoreDNS pods are healthy but one namespace still fails resolutionA hardened namespace loses name resolution after a node-local DNS optimization or add-on change, while the rest of the cluster remains healthy.KubernetesAdvanced18 minProK8S-1261CoreDNS stays Pending on a private EKS clusterK8s incident scenario used for structured troubleshooting practice.KubernetesAdvanced18 minProK8S-1266CoreDNS stays Pending on a private EKS clusterA cluster expansion seems successful until CoreDNS and other essential pods remain Pending despite healthy node registration.KubernetesAdvanced18 minProK8S-104CSI node plugin is healthy but SELinux labeling blocks the kubelet from using the published socketThe DaemonSet looks ready, yet mounts fail because the host path and socket labels do not allow the kubelet domain to connect.KubernetesAdvanced18 minProK8S-112HorizontalPodAutoscaler sees the custom metric intermittentlyAutoscaling seems random because the adapter is reachable, yet TLS validation fails sporadically between control plane components.KubernetesAdvanced18 minProK8S-080Ingress controller leader election lease stayed in the old namespace after a migrationThe new controller deploys cleanly, yet only one replica ever reconciles because the election objects still point at the namespace pattern from the previous release.KubernetesAdvanced18 minProK8S-100Ingress leader election looks healthy but one class still routes nowhereThe controller pods are up, yet routes for one ingress class remain empty because the controller cannot write the status fields other components depend on.KubernetesAdvanced18 minPro